Commit 85bd7d6f2 for imagemagick.org

commit 85bd7d6f2cb64edd1e2f162cefb2f31dad5f7f7f
Author: Cristy <urban-warrior@imagemagick.org>
Date:   Tue Sep 29 19:59:14 2026 -0400

    add pipes security policy

diff --git a/config/policy-limited.xml b/config/policy-limited.xml
index 9261b7dbd..1e052a4ff 100644
--- a/config/policy-limited.xml
+++ b/config/policy-limited.xml
@@ -97,6 +97,8 @@
   <policy domain="path" rights="none" pattern="/etc/*"/>
   <!-- Indirect reads are not permitted. -->
   <policy domain="path" rights="none" pattern="@*"/>
+  <!-- Pipes are not permitted. -->
+  <policy domain="path" rights="none" pattern="|*"/>
   <!-- These image types are security risks on read, but write is fine -->
   <policy domain="module" rights="write" pattern="{MSL,MVG,PDF,PS,SVG,TXT,URL,XPS}"/>
   <!-- This policy sets the number of times to replace content of certain
diff --git a/config/policy-open.xml b/config/policy-open.xml
index 447882f05..4c3c8f36e 100644
--- a/config/policy-open.xml
+++ b/config/policy-open.xml
@@ -148,6 +148,8 @@
   <!-- <policy domain="path" rights="none" pattern="/etc/*"/> -->
   <!-- Indirect reads are not permitted. -->
   <!-- <policy domain="path" rights="none" pattern="@*"/> -->
+  <!-- Pipes are not permitted. -->
+  <!-- <policy domain="path" rights="none" pattern="|*"/> -->
   <!-- These image types are security risks on read, but write is fine -->
   <!-- <policy domain="module" rights="write" pattern="{MSL,MVG,PDF,PS,SVG,TXT,URL,XPS}"/> -->
   <!-- This policy sets the number of times to replace content of certain
diff --git a/config/policy-secure.xml b/config/policy-secure.xml
index 7da9138c9..0babc363a 100644
--- a/config/policy-secure.xml
+++ b/config/policy-secure.xml
@@ -106,6 +106,8 @@
   <policy domain="path" rights="none" pattern="*../*"/>
   <!-- Indirect reading is not permitted. -->
   <policy domain="path" rights="none" pattern="@*"/>
+  <!-- Pipes are not permitted. -->
+  <policy domain="path" rights="none" pattern="|*"/>
   <!-- These image types are security risks on read, but write is fine -->
   <policy domain="module" rights="write" pattern="{MSL,MVG,PDF,PS,SVG,TXT,URL,XPS}"/>
   <!-- This policy sets the number of times to replace content of certain
diff --git a/config/policy-websafe.xml b/config/policy-websafe.xml
index 856ba8897..dbdf81559 100644
--- a/config/policy-websafe.xml
+++ b/config/policy-websafe.xml
@@ -102,6 +102,8 @@
   <policy domain="path" rights="none" pattern="*../*"/>
   <!-- Indirect reading is not permitted. -->
   <policy domain="path" rights="none" pattern="@*"/>
+  <!-- Pipes are not permitted. -->
+  <policy domain="path" rights="none" pattern="|*"/>
   <!-- Deny all image modules and specifically exempt reading or writing
        web-safe image formats. -->
   <policy domain="module" rights="none" pattern="*" />